Data protection
Privacy Policy
Last updated:
This policy explains how personal data may be processed in connection with this website. It is written for this portfolio specifically and is not a generic template.
1. Introduction and scope
This website is the personal professional portfolio of Miguel Ângelo Dias Magalhães. It presents his academic and professional background, skills, projects, experience, certifications, research, international activities and contact details.
The website does not sell products, take payments, take bookings or provide or invoice services directly. Visiting the pages is informational. Any future collaboration depends on separate contact and a separate agreement.
This policy covers personal data that may be processed because you visit the website or because you choose to contact Miguel. It does not cover websites that you open through external links.
2. Controller
The controller of personal data processed for the purposes described here is:
- Miguel Ângelo Dias Magalhães
- Porto, Portugal
- Email: miguel.softeng@gmail.com
There is no data protection officer. Questions and requests about personal data can be sent to the email address above.
3. Technical data and hosting
The website is hosted on GitHub Pages, a static hosting service operated by GitHub. To deliver pages, keep the service available and protect the infrastructure, the hosting provider and related delivery or security infrastructure may process technical data. Depending on how the service is operated, this can include:
- IP address;
- date and time of the request;
- requested resource;
- browser or device user-agent;
- referrer, when the browser sends one;
- diagnostic, cache or security data needed to operate the service.
Miguel does not run a private analytics system on this website and does not have routine access to detailed visitor logs. Any technical records generated by hosting or related infrastructure are processed according to the provider’s own systems and policies.
Further information about GitHub’s processing is available in GitHub’s official privacy documentation, which you can open if you wish:
4. Contact by email
The website does not contain a contact form, account system, newsletter signup or payment flow. The email button opens your own email application with Miguel’s address filled in. No message is sent to Miguel until you decide to send it.
If you send an email, the information you choose to include may be processed in order to read, assess and reply. This can include your name, email address, the content of the message, attachments and any other details you volunteer.
Please do not send passwords, API keys, payment data, identity documents or other highly sensitive information unless it is genuinely necessary and an appropriate channel has been agreed. Ordinary professional contact does not require that material.
5. Purposes and legal bases
Personal data is processed only for specific purposes and on a legal basis under the GDPR:
- Making the website available, keeping it working and protecting it. Technical data needed to deliver and secure the site may be processed on the basis of legitimate interests (Article 6(1)(f) GDPR): operating a public professional portfolio in a stable and reasonably secure way.
- Responding to general and professional messages. If you contact Miguel, the message may be processed on the basis of legitimate interests (Article 6(1)(f) GDPR): understanding the request and answering it.
- Steps prior to a possible contract, when that is what the message is about. If you write about a potential collaboration, project or professional engagement, the data needed to consider that request may be processed under Article 6(1)(b) GDPR. Not every message is a pre-contractual request.
- Legal obligations. Data may be processed where necessary to comply with a legal obligation (Article 6(1)(c) GDPR), for example if an authority makes a valid request.
Sending an email is not treated as consent for unrelated processing. Consent is not used as a catch-all legal basis for this website.
6. Retention
General contact messages are normally kept for up to 24 months after the last relevant interaction. They may be deleted earlier if they are no longer needed.
They may be kept for longer where there is an ongoing professional relationship, a legal obligation, a need to keep evidence, a need to establish, exercise or defend legal claims, or a dispute.
Retention of technical logs is determined by the hosting provider under its own policies. This website does not implement automatic deletion of messages or logs, and no automatic erasure is promised.
7. Recipients and providers
Depending on the situation, personal data may be processed by or made available to:
- the email provider used to receive and store messages sent to the contact address;
- GitHub / GitHub Pages, as the hosting infrastructure;
- technical CDN, caching or security providers integrated into the hosting service, where the hosting provider uses them;
- public authorities, if there is a legal obligation to disclose information.
No other categories of recipient are used for this website at present. The site does not share visitor data with advertisers or analytics companies.
8. International transfers
Some technology providers involved in hosting or email may process data outside the European Economic Area. Where that happens, the transfer is subject to the legal mechanisms that apply at the time and to the provider’s own policies.
This policy does not assert a specific transfer tool, such as an adequacy decision or standard contractual clauses, without a current official confirmation from the relevant provider. If you need more detail about a particular provider, you can consult that provider’s official documentation or ask Miguel using the contact email.
10. External links
The portfolio contains links to other websites, including LinkedIn, GitHub, ORCID, Credly, project pages, client or employer sites and similar destinations. Those links are provided for context. You communicate with those services only if you choose to follow the link. Their content, availability and privacy practices are governed by their own policies.
11. Information published in the portfolio
The portfolio contains information that Miguel has chosen to make public about his own professional path. That is distinct from technical data generated when someone visits the site, and from personal data contained in a private email.
The site also names third parties where that is needed to describe work already carried out:
- co-author names appear in the context of scientific work;
- organisation names, brands and logos identify experience, education, clients, projects or technologies.
Publication does not necessarily mean current affiliation, sponsorship or approval by those persons or organisations. If you are named and you want a correction or removal, you can send a reasoned request to miguel.softeng@gmail.com. Requests will be assessed in good faith. This policy does not claim that every third party has given documented consent to appear on the site.
12. Your rights
Where the GDPR applies, you may have the right to:
- access your personal data;
- rectify inaccurate data;
- erase data, in the cases provided by law;
- restrict processing;
- object to processing based on legitimate interests;
- receive data in a portable format, where the legal conditions are met;
- withdraw consent, but only where processing is actually based on consent;
- lodge a complaint with a supervisory authority.
In Portugal, the supervisory authority is the Comissão Nacional de Proteção de Dados (CNPD). Information about data-subject rights is available on the CNPD website:
https://www.cnpd.pt/cidadaos/direitos/
To handle a request, it may be necessary to confirm your identity in a reasonable way. Identity documents will not be demanded by default, and only information that is actually needed will be asked for.
13. Automated decisions
This website does not make automated decisions with legal or similarly significant effects, and it does not create profiles of visitors.
14. Security
Proportionate measures are used to protect the website and communications, including HTTPS. No website or email channel can be guaranteed to be completely secure, and absolute security is not promised.
15. Changes
This policy may be updated if the website, providers or processing activities change. The date at the top of the page will be revised when that happens.
This page describes how personal data is handled on this website.